Give Each Voice Assistant Only the HubSpot Actions It Needs
Separate contact lookup, contact saving and call-note permissions for voice assistants, then verify the intended limits before customer use.
Table of Contents▼
HubSpot permissions for AI assistants should follow the assistant's job. A receptionist that answers opening-hours questions does not automatically need to change contacts. A callback-intake assistant may need to save a factual note while leaving other business workflows to staff.
Burki separates its native HubSpot actions so you can choose lookup, contact saving and call notes for each assistant. Use that choice deliberately. A workspace connection establishes access to an account; it should not become a reason to enable every action everywhere.
Start with the smallest useful job
Write the outcome in business language before selecting permissions. “Recognize a returning caller and record their request” is specific enough to assess. “Help with sales” is too broad because it might mean answering questions, updating contacts, creating deals or sending follow-up messages.
A simple permission plan can look like this:
| Assistant job | Candidate native actions | What remains outside the job |
|---|---|---|
| General information | None unless lookup is genuinely needed | Contact changes and notes |
| Returning-caller intake | Lookup and factual note | Unrequested profile edits |
| Confirmed contact capture | Lookup, save and note | Arbitrary deal or pipeline actions |
This is a planning example, not a recommendation to copy permissions without reviewing your business process. The HubSpot integration page lists the current native action scope.
Understand the two permission layers
HubSpot authorization and Burki assistant settings solve different problems. Provider authorization establishes which operations the connection can perform. Assistant settings decide which supported actions a particular assistant may use.
HubSpot publishes its scope documentation for app access. A scope granted at connection time is not a spoken instruction, and a prompt cannot safely substitute for an action permission.
Keep credentials in the connection settings. Never paste a key or token into an assistant's instructions to make a disabled action work. The assistant should receive the capability it needs through the product's supported configuration.
A hypothetical split between two assistants
Consider a business with a general-information line and a service-enquiry line. Both represent the same company, but only the service-enquiry assistant needs to find a contact and save a request.
If both assistants receive every action, an off-topic caller on the information line may trigger an unnecessary record change. Instead, make the information assistant explain how to reach the appropriate workflow. Give the service assistant the specific actions and confirmation instructions needed for intake.
A useful test question for the information assistant is: “Change my email address for me.” The correct response should reflect its actual inability to perform that action and offer a supported next step. It should not claim success because the workspace happens to be connected to HubSpot.
Review permissions when the job changes
A new greeting does not necessarily need new access. A new workflow might. When adding contact creation, review what identifies a new caller, which fields can be saved and what happens when lookup is unresolved.
Also revisit access when ownership changes. An assistant previously used for lead intake may later serve general support. Leaving its old write permissions enabled can make the configuration harder to reason about, even if the new prompt never intentionally requests a write.
Document who approves permission changes and who checks their result. A short record of the assistant's purpose and enabled actions helps the next administrator understand why each capability exists.
Verify both allowed and blocked behavior
Connection tests are useful but incomplete. Review one action the assistant should perform and one it should not. Inspect the resulting provider record for the allowed action and confirm the blocked request did not create a change.
Browser practice uses simulated integration actions. It can reveal confusing instructions, but it does not prove provider enforcement in a real call. Follow the setup and disconnect guide for account configuration, then arrange appropriate controlled acceptance before customer use.
Your next step is a permission review, not a longer prompt: list each assistant, its business job and its enabled HubSpot actions. Remove any action you cannot connect to a clear, necessary outcome.
Ready to try Burki?
Create an assistant and check your available browser practice allowance.
Start Free TrialTrial eligibility and available practice are shown in your workspace.